JAVA.SV.LLM.INPUT.UNBOUNDED
Unbounded input passed to an LLM
The JAVA.SV.LLM.INPUT.UNBOUNDED checker identifies unbounded input passed to an LLM.
Vulnerability and risk
Allowing unbounded input to reach an LLM can increase token usage and other resource consumption.
Mitigation and prevention
Validate and limit the size of input before sending it to an LLM.
Vulnerable code example
Copy
import org.springframework.ai.chat.client.ChatClient;
public class Example {
private final ChatClient chatClient;
public Example(ChatClient chatClient) {
this.chatClient = chatClient;
}
public String summarize(String documentText) {
return chatClient.prompt()
.user(documentText) // entire document forwarded with no size check
.call()
.content();
}
}
Fixed code example
Copy
import org.springframework.ai.chat.client.ChatClient;
public class Example {
private final ChatClient chatClient;
public Example(ChatClient chatClient) {
this.chatClient = chatClient;
}
public String summarize(String documentText) {
String boundedText = documentText.length() > 4000
? documentText.substring(0, 4000)
: documentText;
return chatClient.prompt()
.user(boundedText)
.call()
.content();
}
}
External guidance
Security training
Application security training materials provided by Secure Code Warrior.